Microsoft Sets New Record By Releasing Over 650 Patches In One Day
Credit: Pixabay
September’s “Patch Tuesday” is expected to patch over 650 vulnerabilities in Windows alone—the third-highest number in several months. This is thanks to the AI models from Anthropic and OpenAI, which are finding bugs faster than they can be fixed.
The unusually high number of fixes was due to new AI models that accelerated the search for software vulnerabilities. Previously, the Anthropic Mythos model discovered issues in all major operating systems and web browsers, and later, OpenAI released its own cybersecurity model, available to trusted partners.
Microsoft typically patches around 100 vulnerabilities per month, but in June the company released around 200 patches, in July at least 570, and in August, it closed almost 400 vulnerabilities. Now, the September release is expected to exceed 650 patches for
Windows.
At the same time, the large volume of updates places additional burden on companies that need to quickly deploy patches. Administrators must first review updates to ensure they don’t disrupt critical corporate applications, creating a so-called “patch gap” between the disclosure of a vulnerability and its resolution.
This problem is particularly serious due to the speed with which AI can find and analyze vulnerabilities. Anthropic previously reported that Mythos can create working exploits for newly disclosed issues in hours instead of weeks, so delaying patch deployment increases the risk of attacks.
Microsoft previously publicly warned about increasing the volume of updates. In a May post, Tom Gallagher, head of the Microsoft Security Response Center, explained that AI helps find additional issues even in code that has already been thoroughly reviewed. The company attributes this result to a combination of factors: the development of automation, the work of its own engineers, and the participation of independent researchers. All vulnerability reports undergo the usual review and prioritization procedures.
